<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"><channel>
  <title>Big 4 Cyber &amp; IW Threat Dashboard — curated news</title>
  <link>https://unclet67.github.io/cyber-threat-dashboard/</link>
  <description>China / Russia / Iran / North Korea cyber and information-warfare reporting, collected hourly from 27 vetted feeds.</description>
  <item>
    <title>Unpacking “Cruciferra”: An Analysis of a Sophisticated Crypter Service</title>
    <link>https://www.proofpoint.com/us/blog/threat-insight/unpacking-cruciferra-analysis-sophisticated-crypter-service</link>
    <guid isPermaLink="true">https://www.proofpoint.com/us/blog/threat-insight/unpacking-cruciferra-analysis-sophisticated-crypter-service</guid>
    <pubDate>Mon, 20 Jul 2026 20:10:28 GMT</pubDate>
    <category>CN</category>
    <source url="https://www.proofpoint.com/us/blog/threat-insight/unpacking-cruciferra-analysis-sophisticated-crypter-service">Proofpoint Threat Insight</source>
    <description>Key Findings&amp;nbsp; Cruciferra is a sophisticated crypter service used by multiple unrelated cybercriminal threat clusters.&amp;nbsp;&amp;nbsp; It has been observed delivering a wide range of remote access trojans and infostealers.&amp;nbsp; The malware employs extensive defense-evasion capabilities and over 90 variations of cryptographic functions to obfuscate its data and payloads.&amp;nbsp; Proofpoint identified both production and apparent testing variants, indicating the service is under active development.</description>
  </item>
  <item>
    <title>HOLLOWGRAPH malware turns Microsoft 365 calendars into an espionage channel</title>
    <link>https://www.helpnetsecurity.com/2026/07/20/hollowgraph-malware-microsoft-365-calendar/</link>
    <guid isPermaLink="true">https://www.helpnetsecurity.com/2026/07/20/hollowgraph-malware-microsoft-365-calendar/</guid>
    <pubDate>Mon, 20 Jul 2026 17:20:15 GMT</pubDate>
    <category>IR</category>
    <source url="https://www.helpnetsecurity.com/2026/07/20/hollowgraph-malware-microsoft-365-calendar/">Help Net Security</source>
    <description>Microsoft 365 calendars have become a hiding place for espionage malware, with commands and stolen files stashed inside appointments dated to the year 2050, researchers from Group-IB discovered. Targeted campaign tied to Iranian espionage activity The malware, which Group-IB calls HOLLOWGRAPH, is one component of a bigger toolkit the company links with high confidence to the Cavern backdoor framework, a modular espionage toolkit built from separate plugins that each handle a different task, prev</description>
  </item>
  <item>
    <title>Russian Intelligence Hacks IP Cameras to Spy on Military Logistics Across NATO States and Ukraine</title>
    <link>https://thehackernews.com/2026/07/russian-intelligence-hacks-ip-cameras.html</link>
    <guid isPermaLink="true">https://thehackernews.com/2026/07/russian-intelligence-hacks-ip-cameras.html</guid>
    <pubDate>Mon, 20 Jul 2026 12:13:39 GMT</pubDate>
    <category>RU</category>
    <source url="https://thehackernews.com/2026/07/russian-intelligence-hacks-ip-cameras.html">The Hacker News</source>
    <description>At least one Russian intelligence service is systematically hijacking internet-connected security cameras across Europe and Ukraine, using the feeds to watch military transport routes, weapons shipments bound for Kyiv, and the locations of Ukrainian troops. That is the finding of a cybersecurity advisory published July 10 by the AIVD and MIVD, the Netherlands&apos; civilian and military intelligence</description>
  </item>
  <item>
    <title>Russian-Speaking Hacker Uses Google Gemini CLI to Control Botnet of Eight Dental Clinic PCs</title>
    <link>https://thehackernews.com/2026/07/russian-speaking-hacker-uses-google.html</link>
    <guid isPermaLink="true">https://thehackernews.com/2026/07/russian-speaking-hacker-uses-google.html</guid>
    <pubDate>Mon, 20 Jul 2026 09:07:11 GMT</pubDate>
    <category>RU</category>
    <source url="https://thehackernews.com/2026/07/russian-speaking-hacker-uses-google.html">The Hacker News</source>
    <description>A solo Russian-speaking threat actor known as &quot;bandcampro&quot; outsourced a chunk of their operations to Google&apos;s open-source Gemini CLI artificial intelligence (AI) and commandeered a live botnet. The findings come from an analysis of 200 Gemini CLI session logs between March 19 and April 21, 2026, which found the threat actor using AI, among other things, to crack passwords, set up a residential</description>
  </item>
  <item>
    <title>Hackers abuse ViPNet software to target Russian govt agencies</title>
    <link>https://www.bleepingcomputer.com/news/security/hackers-abuse-vipnet-software-to-target-russian-govt-agencies/</link>
    <guid isPermaLink="true">https://www.bleepingcomputer.com/news/security/hackers-abuse-vipnet-software-to-target-russian-govt-agencies/</guid>
    <pubDate>Sun, 19 Jul 2026 14:23:46 GMT</pubDate>
    <category>RU</category>
    <source url="https://www.bleepingcomputer.com/news/security/hackers-abuse-vipnet-software-to-target-russian-govt-agencies/">BleepingComputer</source>
    <description>An advanced threat actor is abusing the update mechanism for the ViPNet private networking product suite to target Russian organizations, including government agencies. [...]</description>
  </item>
  <item>
    <title>UAC-0145 Uses ClickFix CAPTCHAs to Infect Ukrainian Devices wih Malware</title>
    <link>https://thehackernews.com/2026/07/uac-0145-uses-clickfix-captchas-to.html</link>
    <guid isPermaLink="true">https://thehackernews.com/2026/07/uac-0145-uses-clickfix-captchas-to.html</guid>
    <pubDate>Sun, 19 Jul 2026 13:30:55 GMT</pubDate>
    <category>RU</category>
    <source url="https://thehackernews.com/2026/07/uac-0145-uses-clickfix-captchas-to.html">The Hacker News</source>
    <description>Russian state-sponsored threat actors have been observed leveraging the infamous ClickFix strategy to trick Ukrainian targets into infecting their own machines with data-stealing malware. According to the Computer Emergency Response Team of Ukraine (CERT-UA), the activity has been attributed to UAC-0145, a sub-cluster within Sandworm, an advanced hacking unit affiliated with GRU, Russia&apos;s</description>
  </item>
  <item>
    <title>Your Period Tracker Is (Probably) Spying on You</title>
    <link>https://www.wired.com/story/security-news-this-week-your-period-tracker-is-probably-spying-on-you/</link>
    <guid isPermaLink="true">https://www.wired.com/story/security-news-this-week-your-period-tracker-is-probably-spying-on-you/</guid>
    <pubDate>Sat, 18 Jul 2026 10:30:00 GMT</pubDate>
    <category>RU</category>
    <source url="https://www.wired.com/story/security-news-this-week-your-period-tracker-is-probably-spying-on-you/">WIRED — Security</source>
    <description>Plus: Russian cyberspies turn to infrastructure hacking, DHS repeatedly fails to realize it’d been hacked, a breach exposes an AI music generator’s scraping ways, and more.</description>
  </item>
  <item>
    <title>GoldenEyeDog Subgroup Linked to DigiCert Breach and Code-Signing Certificate Theft</title>
    <link>https://thehackernews.com/2026/07/goldeneyedog-subgroup-linked-to.html</link>
    <guid isPermaLink="true">https://thehackernews.com/2026/07/goldeneyedog-subgroup-linked-to.html</guid>
    <pubDate>Fri, 17 Jul 2026 16:39:16 GMT</pubDate>
    <category>CN</category>
    <source url="https://thehackernews.com/2026/07/goldeneyedog-subgroup-linked-to.html">The Hacker News</source>
    <description>Cybersecurity researchers have attributed the April 2026 DigiCert security incident to a threat activity cluster dubbed CylindricalCanine. Expel, which shared technical details of the event, described the threat actor as a sub-group of GoldenEyeDog (aka APT-Q-27, Dragon Breath, and Miuuti Group), a Chinese cybercrime group known for its targeting of the gambling and gaming sectors using</description>
  </item>
  <item>
    <title>Fake Coding Tests Deliver OtterCookie-Aligned Malware Hidden in SVG Flag Images</title>
    <link>https://thehackernews.com/2026/07/north-korea-linked-hackers-hide.html</link>
    <guid isPermaLink="true">https://thehackernews.com/2026/07/north-korea-linked-hackers-hide.html</guid>
    <pubDate>Fri, 17 Jul 2026 13:48:56 GMT</pubDate>
    <category>KP</category>
    <source url="https://thehackernews.com/2026/07/north-korea-linked-hackers-hide.html">The Hacker News</source>
    <description>North Korean threat actors linked to the Contagious Interview campaign have been observed employing steganography in SVG image files to conceal malicious payloads as part of a campaign using fake job postings and coding challenges. &quot;Any user who ran the project ended up with a four-stage payload aligned with OtterCookie: a browser credential and crypto wallet stealer, a file stealer, a</description>
  </item>
  <item>
    <title>Armenia Detains Russian Tourist on U.S. Warrant for REvil Hacker, Lawyers Say Wrong Man</title>
    <link>https://thehackernews.com/2026/07/armenia-detains-russian-tourist-on-us.html</link>
    <guid isPermaLink="true">https://thehackernews.com/2026/07/armenia-detains-russian-tourist-on-us.html</guid>
    <pubDate>Fri, 17 Jul 2026 10:53:31 GMT</pubDate>
    <category>RU</category>
    <source url="https://thehackernews.com/2026/07/armenia-detains-russian-tourist-on-us.html">The Hacker News</source>
    <description>Armenia has held a Russian tourist named Aleksandr Ermakov in a detention center since June 28, on a U.S. extradition request for a REvil ransomware suspect named Aleksandr Ermakov. His wife, Maria Yurova, told REN TV that border officers pulled him out of the departure hall at Yerevan&apos;s Zvartnots airport, held up a phone with a photo of him off his VKontakte page, and walked him into a side</description>
  </item>
  <item>
    <title>Daxin Resurfaces in Taiwan Alongside Stupig Pre-Login SYSTEM Backdoor</title>
    <link>https://thehackernews.com/2026/07/daxin-resurfaces-in-taiwan-alongside.html</link>
    <guid isPermaLink="true">https://thehackernews.com/2026/07/daxin-resurfaces-in-taiwan-alongside.html</guid>
    <pubDate>Thu, 16 Jul 2026 11:17:23 GMT</pubDate>
    <category>CN</category>
    <source url="https://thehackernews.com/2026/07/daxin-resurfaces-in-taiwan-alongside.html">The Hacker News</source>
    <description>An advanced malware previously attributed to a China-linked threat actor has resurfaced after more than four years within a Taiwan manufacturing firm, along with a previously unreported backdoor dubbed Stupig. Daxin (&quot;srt64.sys&quot;), as the kernel-mode rootkit is referred to, was first documented by Broadcom-owned Symantec in March 2022, with evidence indicating its use in targeted attacks aimed</description>
  </item>
  <item>
    <title>UAT-11795 deploys novel Starland RAT and bespoke WLDR C2 implant in financially motivated campaign</title>
    <link>https://blog.talosintelligence.com/uat-11795-deploys-novel-starland-rat-and-bespoke-wldr-c2-implant-in-financially-motivated-campaign/</link>
    <guid isPermaLink="true">https://blog.talosintelligence.com/uat-11795-deploys-novel-starland-rat-and-bespoke-wldr-c2-implant-in-financially-motivated-campaign/</guid>
    <pubDate>Thu, 16 Jul 2026 10:00:01 GMT</pubDate>
    <category>RU</category>
    <source url="https://blog.talosintelligence.com/uat-11795-deploys-novel-starland-rat-and-bespoke-wldr-c2-implant-in-financially-motivated-campaign/">Cisco Talos</source>
    <description>Cisco Talos is disclosing UAT-11795, a sophisticated, Russian-speaking, financially motivated adversary that has been conducting a malicious campaign targeting users in the U.S. and Europe since at least June 2025.</description>
  </item>
  <item>
    <title>&apos;The bots are alive!&apos; Jailbroken Gemini spun up new C2 server for Russian fraudster in just 6 minutes</title>
    <link>https://www.theregister.com/research/2026/07/14/the-bots-are-alive-jailbroken-gemini-spun-up-new-c2-server-for-russian-fraudster-in-just-6-minutes/5270131</link>
    <guid isPermaLink="true">https://www.theregister.com/research/2026/07/14/the-bots-are-alive-jailbroken-gemini-spun-up-new-c2-server-for-russian-fraudster-in-just-6-minutes/5270131</guid>
    <pubDate>Tue, 14 Jul 2026 12:15:00 GMT</pubDate>
    <category>RU</category>
    <source url="https://www.theregister.com/research/2026/07/14/the-bots-are-alive-jailbroken-gemini-spun-up-new-c2-server-for-russian-fraudster-in-just-6-minutes/5270131">The Register — Security</source>
    <description>Human did 10% of the job, AI did 90%</description>
  </item>
  <item>
    <title>Improve Router Hygiene to Protect Against Russian State-Sponsored Targeting</title>
    <link>https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-194a</link>
    <guid isPermaLink="true">https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-194a</guid>
    <pubDate>Mon, 13 Jul 2026 12:00:00 GMT</pubDate>
    <category>CN</category>
    <source url="https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-194a">CISA Advisories</source>
    <description>Russian Government-Sponsored Activity Targets Poorly Configured and Vulnerable Devices Across Critical Sectors Executive summary Russian Federal Security Service (FSB) Center 16 cyber actors continue to exploit poorly configured and vulnerable networking devices worldwide, opportunistically compromising multiple critical infrastructure sector networks. This joint Cybersecurity Advisory (CSA) builds on FBI’s Russian Government Cyber Actors Targeting Networking Devices, Critical Infrastructure Pub</description>
  </item>
  <item>
    <title>Improve Router Hygiene to Protect Against Russian State-Sponsored Targeting</title>
    <link>https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-194a</link>
    <guid isPermaLink="true">https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-194a</guid>
    <pubDate>Mon, 13 Jul 2026 12:00:00 GMT</pubDate>
    <category>RU</category>
    <source url="https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-194a">CISA Advisories</source>
    <description>Russian Government-Sponsored Activity Targets Poorly Configured and Vulnerable Devices Across Critical Sectors Executive summary Russian Federal Security Service (FSB) Center 16 cyber actors continue to exploit poorly configured and vulnerable networking devices worldwide, opportunistically compromising multiple critical infrastructure sector networks. This joint Cybersecurity Advisory (CSA) builds on FBI’s Russian Government Cyber Actors Targeting Networking Devices, Critical Infrastructure Pub</description>
  </item>
  <item>
    <title>UK and Allies urge critical sectors to improve defences against Russian intelligence targeting</title>
    <link>https://www.ncsc.gov.uk/news/uk-and-allies-urge-critical-sectors-to-improve-defences-against-russian-intelligence-targeting</link>
    <guid isPermaLink="true">https://www.ncsc.gov.uk/news/uk-and-allies-urge-critical-sectors-to-improve-defences-against-russian-intelligence-targeting</guid>
    <pubDate>Mon, 13 Jul 2026 12:00:00 GMT</pubDate>
    <category>RU</category>
    <source url="https://www.ncsc.gov.uk/news/uk-and-allies-urge-critical-sectors-to-improve-defences-against-russian-intelligence-targeting">NCSC UK</source>
    <description>New advisory highlights Russian state cyber actors’ global exploitation of poorly configured routers</description>
  </item>
  <item>
    <title>Iran&apos;s Cyber Crosshairs Focus Beyond Critical Infrastructure</title>
    <link>https://www.darkreading.com/cyber-risk/iran-cyber-crosshairs-beyond-critical-infrastructure</link>
    <guid isPermaLink="true">https://www.darkreading.com/cyber-risk/iran-cyber-crosshairs-beyond-critical-infrastructure</guid>
    <pubDate>Thu, 09 Jul 2026 20:32:00 GMT</pubDate>
    <category>IR</category>
    <source url="https://www.darkreading.com/cyber-risk/iran-cyber-crosshairs-beyond-critical-infrastructure">Dark Reading</source>
    <description>Obscurity isn&apos;t a defense. If your company has any Internet-facing vulnerability, you&apos;re at risk from multiple threats.</description>
  </item>
  <item>
    <title>China tells devs to ditch Claude Code over &apos;backdoor code&apos; fears</title>
    <link>https://www.theregister.com/security/2026/07/08/china-ditch-older-claude-versions-with-backdoor-code/5268371</link>
    <guid isPermaLink="true">https://www.theregister.com/security/2026/07/08/china-ditch-older-claude-versions-with-backdoor-code/5268371</guid>
    <pubDate>Wed, 08 Jul 2026 13:58:07 GMT</pubDate>
    <category>CN</category>
    <source url="https://www.theregister.com/security/2026/07/08/china-ditch-older-claude-versions-with-backdoor-code/5268371">The Register — Security</source>
    <description>National vulnerability database claims monitoring mechanism can forward Chinese users&apos; data to remote servers</description>
  </item>
  <item>
    <title>What Happens if China Hacks the US Water Supply? I Went to a Secret War Game to Find Out</title>
    <link>https://www.wired.com/story/what-happens-if-china-hacks-the-us-water-supply-war-game-volt-typhoon/</link>
    <guid isPermaLink="true">https://www.wired.com/story/what-happens-if-china-hacks-the-us-water-supply-war-game-volt-typhoon/</guid>
    <pubDate>Wed, 08 Jul 2026 10:00:00 GMT</pubDate>
    <category>CN</category>
    <source url="https://www.wired.com/story/what-happens-if-china-hacks-the-us-water-supply-war-game-volt-typhoon/">WIRED — Security</source>
    <description>Burst water mains. Evacuated hospitals. In a closed-door simulation, insurers played out their response to a mass disruption by China’s Volt Typhoon hackers—and found a nightmare scenario.</description>
  </item>
  <item>
    <title>One Email Closer to the Edge: UNK_MassTraction &amp; the Physics of Exploitation</title>
    <link>https://www.proofpoint.com/us/blog/threat-insight/one-email-closer-edge-unkmasstraction-physics-exploitation</link>
    <guid isPermaLink="true">https://www.proofpoint.com/us/blog/threat-insight/one-email-closer-edge-unkmasstraction-physics-exploitation</guid>
    <pubDate>Tue, 07 Jul 2026 15:47:12 GMT</pubDate>
    <category>CN</category>
    <source url="https://www.proofpoint.com/us/blog/threat-insight/one-email-closer-edge-unkmasstraction-physics-exploitation">Proofpoint Threat Insight</source>
    <description>Analyst note: Proofpoint uses the UNK_ designator to define clusters of activity that are still developing and have not been observed for long enough to receive a numerical TA designation. Key Findings Since May 2026, Proofpoint Threat Research has been tracking a suspected China-aligned threat cluster named UNK_MassTraction exploiting Roundcube mailservers belonging to the physics and engineering departments of US and Canadian universities. The campaigns exploit multiple n-day vulnerabilities i</description>
  </item>
  <item>
    <title>Spain collars alleged pro-Russia hacktivist after FBI tip-off</title>
    <link>https://www.theregister.com/security/2026/07/07/alleged-pro-russia-hacktivist-arrested-in-palencia/5267569</link>
    <guid isPermaLink="true">https://www.theregister.com/security/2026/07/07/alleged-pro-russia-hacktivist-arrested-in-palencia/5267569</guid>
    <pubDate>Tue, 07 Jul 2026 10:30:50 GMT</pubDate>
    <category>RU</category>
    <source url="https://www.theregister.com/security/2026/07/07/alleged-pro-russia-hacktivist-arrested-in-palencia/5267569">The Register — Security</source>
    <description>Palencia man suspected of links to CARR, Z-Pentest, and NoName057(16), plus helping a Ukrainian hacker flee to Russia</description>
  </item>
  <item>
    <title>Cavern Manticore: Exposing Iran-Linked Modular C2 Framework</title>
    <link>https://research.checkpoint.com/2026/cavern-manticore-exposing-iran-linked-modular-c2-framework/</link>
    <guid isPermaLink="true">https://research.checkpoint.com/2026/cavern-manticore-exposing-iran-linked-modular-c2-framework/</guid>
    <pubDate>Mon, 06 Jul 2026 12:25:02 GMT</pubDate>
    <category>IR</category>
    <source url="https://research.checkpoint.com/2026/cavern-manticore-exposing-iran-linked-modular-c2-framework/">Check Point Research</source>
    <description>Key Points Introduction Since early 2026, Check Point Research (CPR) has tracked a new modular command-and-control framework used by Cavern Manticore, an Iran-nexus APT group primarily targeting Israeli organizations, with a focus on IT providers, and government sectors. Cavern Manticore is an Iran MOIS (Ministry of Intelligence and Security)-linked actor, with links to the OilRig […] The post Cavern Manticore: Exposing Iran-Linked Modular C2 Framework appeared first on Check Point Research .</description>
  </item>
  <item>
    <title>Armored Likho digging a snake pit: inside the covert BusySnake Stealer campaign</title>
    <link>https://securelist.com/tr/armored-likho-apt-with-busysnake-stealer/120292/</link>
    <guid isPermaLink="true">https://securelist.com/tr/armored-likho-apt-with-busysnake-stealer/120292/</guid>
    <pubDate>Fri, 03 Jul 2026 10:00:33 GMT</pubDate>
    <category>RU</category>
    <source url="https://securelist.com/tr/armored-likho-apt-with-busysnake-stealer/120292/">Kaspersky Securelist</source>
    <description>An inside look at the active Armored Likho APT campaign. The attackers are using spear-phishing, AI-generated loaders, and a new Python-based tool, BusySnake Stealer, to target organizations in Russia, Kazakhstan, and Brazil.</description>
  </item>
  <item>
    <title>Gamaredon in 2025: Leveraging tunnels, workers, dead drops, and new alliances</title>
    <link>https://www.welivesecurity.com/en/eset-research/gamaredon-2025-leveraging-tunnels-workers-dead-drops-new-alliances/</link>
    <guid isPermaLink="true">https://www.welivesecurity.com/en/eset-research/gamaredon-2025-leveraging-tunnels-workers-dead-drops-new-alliances/</guid>
    <pubDate>Thu, 25 Jun 2026 08:45:00 GMT</pubDate>
    <category>RU</category>
    <source url="https://www.welivesecurity.com/en/eset-research/gamaredon-2025-leveraging-tunnels-workers-dead-drops-new-alliances/">ESET WeLiveSecurity</source>
    <description>ESET Research analyzes Gamaredon’s new toolset and the group’s growing reliance on legitimate online services to hide its C&amp;C infrastructure and exfiltrate stolen data</description>
  </item>
  <item>
    <title>Sayonara, SocGholish: Operation Endgame Disrupts Major Cybercrime Operation</title>
    <link>https://www.proofpoint.com/us/blog/threat-insight/sayonara-socgholish-operation-endgame-disrupts-major-cybercrime-operation</link>
    <guid isPermaLink="true">https://www.proofpoint.com/us/blog/threat-insight/sayonara-socgholish-operation-endgame-disrupts-major-cybercrime-operation</guid>
    <pubDate>Wed, 17 Jun 2026 17:59:58 GMT</pubDate>
    <category>RU</category>
    <source url="https://www.proofpoint.com/us/blog/threat-insight/sayonara-socgholish-operation-endgame-disrupts-major-cybercrime-operation">Proofpoint Threat Insight</source>
    <description>Key Findings&amp;nbsp; Global law enforcement and private sector partners worked to disrupt activity related to TA569, as part of Operation Endgame.&amp;nbsp; TA569 is one of the most prominent&amp;nbsp;cybercriminal&amp;nbsp;threat groups in Proofpoint threat data, which our researchers have tracked since 2018.&amp;nbsp;&amp;nbsp; TA569’s&amp;nbsp;SocGholish&amp;nbsp;inject activity has been linked to major ransomware families and criminal syndicates.&amp;nbsp; The&amp;nbsp;law enforcement&amp;nbsp;actions included disrupting their serve</description>
  </item>
  <item>
    <title>Don&apos;t Fear the Repo: UNK_DeadDrop Phishing Campaign Targets Developers to Steal Cryptocurrency</title>
    <link>https://www.proofpoint.com/us/blog/threat-insight/dont-fear-repo-unkdeaddrop-phishing-campaign-targets-developers-steal</link>
    <guid isPermaLink="true">https://www.proofpoint.com/us/blog/threat-insight/dont-fear-repo-unkdeaddrop-phishing-campaign-targets-developers-steal</guid>
    <pubDate>Mon, 08 Jun 2026 15:11:53 GMT</pubDate>
    <category>KP</category>
    <source url="https://www.proofpoint.com/us/blog/threat-insight/dont-fear-repo-unkdeaddrop-phishing-campaign-targets-developers-steal">Proofpoint Threat Insight</source>
    <description>By Saher Naumaan, Carlos Rubio, and the Proofpoint Threat Research Team Key Findings Between April and May 2026, Proofpoint Threat Research observed a likely North Korean threat actor conducting phishing campaigns using developer role recruitment or code review themes to targets in close to 100 organizations in finance, cryptocurrency, education, technology, and several other sectors. Proofpoint clusters this activity under the name UNK_DeadDrop. The infection chain begins with emails containing</description>
  </item>
  <item>
    <title>TA4922: The Suspected Chinese Crime Group is Going Global</title>
    <link>https://www.proofpoint.com/us/blog/threat-insight/ta4922-suspected-chinese-crime-group-going-global</link>
    <guid isPermaLink="true">https://www.proofpoint.com/us/blog/threat-insight/ta4922-suspected-chinese-crime-group-going-global</guid>
    <pubDate>Wed, 03 Jun 2026 17:06:32 GMT</pubDate>
    <category>CN</category>
    <source url="https://www.proofpoint.com/us/blog/threat-insight/ta4922-suspected-chinese-crime-group-going-global">Proofpoint Threat Insight</source>
    <description>Key Findings:&amp;nbsp; TA4922 is a highly sophisticated threat actor&amp;nbsp;demonstrating&amp;nbsp;a rapid operational tempo and continually evolving malware arsenal.&amp;nbsp; The group has been&amp;nbsp;observed&amp;nbsp;using multiple malware families including Atlas RAT,&amp;nbsp;RomulusLoader,&amp;nbsp;SilentRunLoader, and&amp;nbsp;ValleyRAT&amp;nbsp;(Winos4.0), among others.&amp;nbsp; TA4922 relies on localized lures often themed around HR, payroll, tax, and invoicing to convince targets across multiple regions. In recent months,</description>
  </item>
  <item>
    <title>More CVEs, Same Playbook: 2026 Vulnerability Exploitation in the Wild</title>
    <link>https://www.proofpoint.com/us/blog/threat-insight/more-cves-same-playbook-2026-vulnerability-exploitation-wild</link>
    <guid isPermaLink="true">https://www.proofpoint.com/us/blog/threat-insight/more-cves-same-playbook-2026-vulnerability-exploitation-wild</guid>
    <pubDate>Wed, 27 May 2026 15:00:00 GMT</pubDate>
    <category>RU</category>
    <source url="https://www.proofpoint.com/us/blog/threat-insight/more-cves-same-playbook-2026-vulnerability-exploitation-wild">Proofpoint Threat Insight</source>
    <description>Executive Summary The CVE Landscape Has Changed. The Threat Actors Haven&apos;t.&amp;nbsp; Proofpoint&apos;s dual telemetry streams — targeted&amp;nbsp;attack&amp;nbsp;visibility covering hundreds of millions of messages daily, and a global network sensor array that generated over 3 million alerts&amp;nbsp;and&amp;nbsp;identified&amp;nbsp;four undisclosed CVEs&amp;nbsp;in 2026 to date — present a consistent picture:&amp;nbsp;attackers are opportunistic. They grab newly published CVEs when public proof-of-concept code appears, chain them</description>
  </item>
  <item>
    <title>More CVEs, Same Playbook: 2026 Vulnerability Exploitation in the Wild</title>
    <link>https://www.proofpoint.com/us/blog/threat-insight/more-cves-same-playbook-2026-vulnerability-exploitation-wild</link>
    <guid isPermaLink="true">https://www.proofpoint.com/us/blog/threat-insight/more-cves-same-playbook-2026-vulnerability-exploitation-wild</guid>
    <pubDate>Wed, 27 May 2026 15:00:00 GMT</pubDate>
    <category>KP</category>
    <source url="https://www.proofpoint.com/us/blog/threat-insight/more-cves-same-playbook-2026-vulnerability-exploitation-wild">Proofpoint Threat Insight</source>
    <description>Executive Summary The CVE Landscape Has Changed. The Threat Actors Haven&apos;t.&amp;nbsp; Proofpoint&apos;s dual telemetry streams — targeted&amp;nbsp;attack&amp;nbsp;visibility covering hundreds of millions of messages daily, and a global network sensor array that generated over 3 million alerts&amp;nbsp;and&amp;nbsp;identified&amp;nbsp;four undisclosed CVEs&amp;nbsp;in 2026 to date — present a consistent picture:&amp;nbsp;attackers are opportunistic. They grab newly published CVEs when public proof-of-concept code appears, chain them</description>
  </item>
  <item>
    <title>Netherlands Seizes 800 Servers, Arrests 2 for Aiding Cyberattacks</title>
    <link>https://krebsonsecurity.com/2026/05/netherlands-seizes-800-servers-arrests-2-for-aiding-cyberattacks/</link>
    <guid isPermaLink="true">https://krebsonsecurity.com/2026/05/netherlands-seizes-800-servers-arrests-2-for-aiding-cyberattacks/</guid>
    <pubDate>Mon, 25 May 2026 13:21:49 GMT</pubDate>
    <category>RU</category>
    <source url="https://krebsonsecurity.com/2026/05/netherlands-seizes-800-servers-arrests-2-for-aiding-cyberattacks/">Krebs on Security</source>
    <description>Authorities in the Netherlands have arrested the co-owners of two related Internet hosting companies for operating IT infrastructure used by Russia to carry out cyberattacks, influence operations and disinformation campaigns inside the European Union. The two men were the focus of a 2025 KrebsOnSecurity story about how their hosting companies had assumed control over the technical infrastructure of Stark Industries Solutions, an Internet service provider sanctioned last year by the EU as a frequ</description>
  </item>
  <item>
    <title>This month in security with Tony Anscombe – April 2026 edition</title>
    <link>https://www.welivesecurity.com/en/videos/month-security-tony-anscombe-april-2026/</link>
    <guid isPermaLink="true">https://www.welivesecurity.com/en/videos/month-security-tony-anscombe-april-2026/</guid>
    <pubDate>Thu, 30 Apr 2026 09:00:00 GMT</pubDate>
    <category>IR</category>
    <source url="https://www.welivesecurity.com/en/videos/month-security-tony-anscombe-april-2026/">ESET WeLiveSecurity</source>
    <description>Warnings about helpdesk impersonation scams and Iran-linked hackers targeting critical sectors in the US, plus the most damaging scams of 2025 - here&apos;s some of what made the headlines this month</description>
  </item>
  <item>
    <title>Executive Summary: Defending against China-nexus covert networks of compromised devices</title>
    <link>https://www.ncsc.gov.uk/news/executive-summary-defending-against-china-nexus-covert-networks-of-compromised-devices</link>
    <guid isPermaLink="true">https://www.ncsc.gov.uk/news/executive-summary-defending-against-china-nexus-covert-networks-of-compromised-devices</guid>
    <pubDate>Thu, 23 Apr 2026 12:00:00 GMT</pubDate>
    <category>CN</category>
    <source url="https://www.ncsc.gov.uk/news/executive-summary-defending-against-china-nexus-covert-networks-of-compromised-devices">NCSC UK</source>
    <description>Organisations should map and baseline their edge device traffic, especially VPN and remote access connections, and adopt dynamic threat feed filtering that includes known covert network indicators.</description>
  </item>
  <item>
    <title>International cyber agencies share fresh advice to defend against China-linked covert networks</title>
    <link>https://www.ncsc.gov.uk/news/international-cyber-agencies-fresh-advice-defend-against-china-linked-covert-networks</link>
    <guid isPermaLink="true">https://www.ncsc.gov.uk/news/international-cyber-agencies-fresh-advice-defend-against-china-linked-covert-networks</guid>
    <pubDate>Thu, 23 Apr 2026 12:00:00 GMT</pubDate>
    <category>CN</category>
    <source url="https://www.ncsc.gov.uk/news/international-cyber-agencies-fresh-advice-defend-against-china-linked-covert-networks">NCSC UK</source>
    <description>New advisory highlights how to defend against attacker tactics believed to be used by China-linked actors to hide malicious cyber activity.</description>
  </item>
  <item>
    <title>GopherWhisper: A burrow full of malware</title>
    <link>https://www.welivesecurity.com/en/eset-research/gopherwhisper-burrow-full-malware/</link>
    <guid isPermaLink="true">https://www.welivesecurity.com/en/eset-research/gopherwhisper-burrow-full-malware/</guid>
    <pubDate>Thu, 23 Apr 2026 08:59:18 GMT</pubDate>
    <category>CN</category>
    <source url="https://www.welivesecurity.com/en/eset-research/gopherwhisper-burrow-full-malware/">ESET WeLiveSecurity</source>
    <description>ESET Research has discovered a new China-aligned APT group that we’ve named GopherWhisper, which targets Mongolian governmental institutions</description>
  </item>
</channel></rss>
